BladeOne.php
2 years ago
CSV.php
9 months ago
Calculations.php
2 years ago
Currency.php
8 months ago
Device.php
1 year ago
Device_Cache.php
2 years ago
Dir.php
5 months ago
Format.php
5 months ago
Link_Validator.php
6 months ago
Number_Formatter.php
5 months ago
Obj.php
6 months ago
Request.php
11 months ago
Salt.php
1 year ago
Security.php
1 year ago
Server.php
2 years ago
Singleton.php
2 years ago
String_Util.php
2 years ago
Timezone.php
5 months ago
URL.php
6 months ago
WP_Async_Request.php
1 year ago
Request.php
161 lines
| 1 | <?php |
| 2 | |
| 3 | namespace IAWP\Utils; |
| 4 | |
| 5 | use IAWPSCOPED\Illuminate\Support\Str; |
| 6 | use IAWPSCOPED\IPLib\Factory; |
| 7 | /** @internal */ |
| 8 | class Request |
| 9 | { |
| 10 | public static function get_post_array(string $field) : ?array |
| 11 | { |
| 12 | if (!\array_key_exists($field, $_POST) || !\is_array($_POST[$field])) { |
| 13 | return null; |
| 14 | } |
| 15 | return \rest_sanitize_array($_POST[$field]); |
| 16 | } |
| 17 | public static function get_post_string(string $field) : ?string |
| 18 | { |
| 19 | if (!\array_key_exists($field, $_POST)) { |
| 20 | return null; |
| 21 | } |
| 22 | return \sanitize_text_field($_POST[$field]); |
| 23 | } |
| 24 | public static function query(string $field) : ?string |
| 25 | { |
| 26 | if (empty($_GET[$field])) { |
| 27 | return null; |
| 28 | } |
| 29 | return \sanitize_text_field($_GET[$field]); |
| 30 | } |
| 31 | public static function query_int(string $field) : ?int |
| 32 | { |
| 33 | $result = \filter_input(\INPUT_GET, $field, \FILTER_VALIDATE_INT); |
| 34 | if (!\is_int($result)) { |
| 35 | return null; |
| 36 | } |
| 37 | return $result; |
| 38 | } |
| 39 | public static function query_array(string $field) : ?array |
| 40 | { |
| 41 | if (empty($_GET[$field]) || !\is_array($_GET[$field])) { |
| 42 | return null; |
| 43 | } |
| 44 | $array = []; |
| 45 | foreach ($_GET[$field] as $item) { |
| 46 | if (!\is_string($item)) { |
| 47 | continue; |
| 48 | } |
| 49 | $array[] = \sanitize_text_field($item); |
| 50 | } |
| 51 | return $array; |
| 52 | } |
| 53 | public static function path_relative_to_site_url($url = null) |
| 54 | { |
| 55 | if (\is_null($url)) { |
| 56 | $url = self::url(); |
| 57 | } |
| 58 | $site_url = \site_url(); |
| 59 | if ($url == $site_url) { |
| 60 | return '/'; |
| 61 | } elseif (\substr($url, 0, \strlen($site_url)) == $site_url) { |
| 62 | return \substr($url, \strlen($site_url)); |
| 63 | } else { |
| 64 | return $url; |
| 65 | } |
| 66 | } |
| 67 | public static function ip() |
| 68 | { |
| 69 | if (\defined('IAWP_TEST_IP')) { |
| 70 | return \IAWP_TEST_IP; |
| 71 | } |
| 72 | $headers = self::ip_headers(); |
| 73 | if (\is_string(self::custom_ip_header())) { |
| 74 | \array_unshift($headers, self::custom_ip_header()); |
| 75 | } |
| 76 | foreach ($headers as $header) { |
| 77 | if (isset($_SERVER[$header])) { |
| 78 | return \explode(',', $_SERVER[$header])[0]; |
| 79 | } |
| 80 | } |
| 81 | return null; |
| 82 | } |
| 83 | public static function custom_ip_header() : ?string |
| 84 | { |
| 85 | // add_filter('iawp_header_with_ip_address', function () { |
| 86 | // return 'CUSTOM_HEADER_NAME'; |
| 87 | // }); |
| 88 | $user_defined_header = \apply_filters('iawp_header_with_ip_address', null); |
| 89 | if (!\is_string($user_defined_header)) { |
| 90 | return null; |
| 91 | } |
| 92 | $user_defined_header = \IAWP\Utils\Security::string($user_defined_header); |
| 93 | if (Str::of($user_defined_header)->test('/^[a-zA-Z_]+$/')) { |
| 94 | return $user_defined_header; |
| 95 | } |
| 96 | return null; |
| 97 | } |
| 98 | public static function user_agent() |
| 99 | { |
| 100 | return $_SERVER['HTTP_USER_AGENT']; |
| 101 | } |
| 102 | public static function is_ip_address_blocked() : bool |
| 103 | { |
| 104 | $blocked_ips = \IAWPSCOPED\iawp()->get_option('iawp_blocked_ips', []); |
| 105 | // No address could be blocked |
| 106 | if (\count($blocked_ips) == 0) { |
| 107 | return \false; |
| 108 | } |
| 109 | $visitor_address = Factory::parseAddressString(self::ip()); |
| 110 | // We cannot block invalid ip addresses |
| 111 | if ($visitor_address === null) { |
| 112 | return \false; |
| 113 | } |
| 114 | foreach ($blocked_ips as $blocked_ip) { |
| 115 | $blocked_range = Factory::parseRangeString($blocked_ip); |
| 116 | // We cannot check an ip address against an invalid range |
| 117 | if ($blocked_range === null) { |
| 118 | continue; |
| 119 | } |
| 120 | // If the address matches this particular blocked range, then the ip address is indeed blocked |
| 121 | if ($blocked_range->contains($visitor_address)) { |
| 122 | return \true; |
| 123 | } |
| 124 | } |
| 125 | return \false; |
| 126 | } |
| 127 | /** |
| 128 | * @return string[] |
| 129 | */ |
| 130 | public static function ip_headers() : array |
| 131 | { |
| 132 | return ['HTTP_X_FORWARDED_FOR', 'HTTP_X_FORWARDED', 'HTTP_FORWARDED_FOR', 'HTTP_FORWARDED', 'REMOTE_ADDR', 'HTTP_CF_CONNECTING_IP', 'HTTP_CLIENT_IP', 'HTTP_INCAP_CLIENT_IP', 'HTTP_CF_CONNECTING_IP']; |
| 133 | } |
| 134 | public static function is_blocked_user_role() : bool |
| 135 | { |
| 136 | $blocked_roles = \IAWPSCOPED\iawp()->get_option('iawp_blocked_roles', ['administrator']); |
| 137 | foreach (\wp_get_current_user()->roles as $visitor_role) { |
| 138 | if (\in_array($visitor_role, $blocked_roles)) { |
| 139 | return \true; |
| 140 | } |
| 141 | } |
| 142 | return \false; |
| 143 | } |
| 144 | private static function scheme() |
| 145 | { |
| 146 | if (!empty($_SERVER['REQUEST_SCHEME']) && $_SERVER['REQUEST_SCHEME'] == 'https' || !empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] == 'on' || !empty($_SERVER['SERVER_PORT']) && $_SERVER['SERVER_PORT'] == '443') { |
| 147 | return 'https'; |
| 148 | } else { |
| 149 | return 'http'; |
| 150 | } |
| 151 | } |
| 152 | private static function url() |
| 153 | { |
| 154 | if (!empty($_SERVER['HTTP_HOST']) && !empty($_SERVER['REQUEST_URI'])) { |
| 155 | return \esc_url_raw(self::scheme() . '://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']); |
| 156 | } else { |
| 157 | return null; |
| 158 | } |
| 159 | } |
| 160 | } |
| 161 |